Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Vk All In One Expansion Unit — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
- Slug:
vk-all-in-one-expansion-unit
- 100000+ instalaciones activas
facebook page plugingoogle analyticsog tagsrelated postssitemap
Estado de mantenimiento
- Última versión conocida: 9.118.0
- Requiere PHP: 7.4+
- PHP máximo soportado (analizado): 8.4
Vulnerabilidades conocidas
12 CVEs conocidos registrados para Vk All In One Expansion Unit.
Reportadas entre 2023 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-39483
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4 |
— |
Media
6,5
|
< 9.113.4
|
9.113.4 |
2026-03-23 |
✓ corregido en la última versión
|
|
CVE-2025-11737
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 9.112.4
|
9.112.4 |
2026-02-17 |
✓ corregido en la última versión
|
|
CVE-2025-11267
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2 |
Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) |
Media
6,4
|
< 9.112.2
|
9.112.2 |
2025-11-17 |
✓ corregido en la última versión
|
|
CVE-2025-11265
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2 |
Neutralización incorrecta de etiquetas HTML relacionadas con scripts en una página web (XSS básico) |
Media
6,4
|
< 9.112.2
|
9.112.2 |
2025-11-17 |
✓ corregido en la última versión
|
|
CVE-2024-52268
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.100.1.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
4,8
|
< 9.100.1.0
|
9.100.1.0 |
2024-11-13 |
✓ corregido en la última versión
|
|
CVE-2024-37956
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.99.2.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 9.99.2.0
|
9.99.2.0 |
2024-07-10 |
✓ corregido en la última versión
|
|
CVE-2024-2093
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.96.0.0 |
Exposición de información sensible a un actor no autorizado |
Media
5,3
|
< 9.96.0.0
|
9.96.0.0 |
2024-03-26 |
✓ corregido en la última versión
|
|
CVE-2024-2170
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.97.0.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 9.97.0.0
|
9.97.0.0 |
2024-03-25 |
✓ corregido en la última versión
|
CVE-2026-39483
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.113.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-11737
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns_title' parameter in all versions up to, and including, 9.112.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-11267
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_css' parameter in all versions up to, and including, 9.112.1. This is due to insufficient input sanitization and output escaping on the user-supplied Custom CSS value. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-11265
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta_url' and 'vkExUnit_cta_button_text' parameters in all versions up to, and including, 9.112.1. This is due to a logic error in the CTA save function that reads sanitization callbacks from the wrong variable ($custom_field_name instead of $custom_field_options), causing the sanitization to never be applied. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that execute when a user accesses an injected page.",
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-52268
"Custom Alert Content" of WordPress Plugin "VK All in One Expansion Unit" provided by Vektor,Inc. contains a stored cross-site scripting vulnerability (CWE-79). Umeda Yuugo of Tokyo Denki University reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
jvndb.jvn.jp
CVE-2024-37956
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.99.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-2093
Update the WordPress VK All in One Expansion Unit plugin to the latest available version (at least 9.96.0.0).
Krzysztof Zając - CERT PL discovered and reported this Sensitive Data Exposure vulnerability in WordPress VK All in One Expansion Unit Plugin. This vulnerability has been fixed in version 9.96.0.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-2170
Update the WordPress VK All in One Expansion Unit plugin to the latest available version (at least 9.97.0.0).
Ngô Thiên An (ancorn_) - VNPT-VCI ST discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress VK All in One Expansion Unit Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.97.0.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 7 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-27926
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 9.88.2.0
|
9.88.2.0 |
2023-05-23 |
✓ corregido en la última versión
|
|
CVE-2023-28367
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 9.88.2.0
|
9.88.2.0 |
2023-05-23 |
✓ corregido en la última versión
|
|
—
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0 |
— |
Desconocido
|
< 9.88.2.0
|
9.88.2.0 |
2023-05-09 |
✓ corregido en la última versión
|
|
CVE-2023-0937
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 9.87.1.0
|
9.87.1.0 |
2023-03-20 |
✓ corregido en la última versión
|
|
—
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0 |
— |
Desconocido
|
< 9.87.1.0
|
9.87.1.0 |
2023-02-23 |
✓ corregido en la última versión
|
|
—
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0 |
— |
Desconocido
|
< 9.87.1.0
|
9.87.1.0 |
2023-02-22 |
✓ corregido en la última versión
|
|
CVE-2023-0230
|
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.86.0.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 9.86.0.0
|
9.86.0.0 |
2023-02-03 |
✓ corregido en la última versión
|
CVE-2023-27926
Cross-site scripting vulnerability in Profile setting function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2023-28367
Cross-site scripting vulnerability in CTA post function of VK All in One Expansion Unit 9.88.1.0 and earlier allows a remote authenticated attacker to inject an arbitrary script.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.88.2.0
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile setting functionality in versions up to, and including, 9.88.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-0937
The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0
Update the WordPress VK All in One Expansion Unit plugin to the latest available version (at least 9.87.1.0).
WordFence discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress VK All in One Expansion Unit Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.87.1.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.87.1.0
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘$_SERVER['REQUEST_URI']’ parameter in versions up to, and including, 9.87.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This only works in older browsers.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-0230
Update the WordPress VK All in One Expansion Unit plugin to the latest available version (at least 9.86.0.0).
Lana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress VK All in One Expansion Unit Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 9.86.0.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Mantén Vk All In One Expansion Unit actualizado — 9.118.0 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas